Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia 7: MGASA-2019-0420 Moderate: Roundcube Homograph Attack

mageia
Calendar Grey December 31, 2019
Dist Mageia Esm H88
Roundcube Webmail upgrade tackles Punycode issues, reducing risks of homograph threats for Mageia 7.
The updated package fixes a security vulnerability: Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks

Summary

The updated package fixes a security vulnerability:
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks. (CVE-2019-15237)

References

- https://bugs.mageia.org/show_bug.cgi?id=25944

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TFFMSO5WKEYSGMTZPZFF4ZADUJ57PRN5/

- https://www.cve.org/CVERecord?id=CVE-2019-15237

Resolution

SRPMS

- 7/core/roundcubemail-1.3.10-1.mga7

Publication date: 31 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0420.html
Type: security
CVE: CVE-2019-15237

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here